Docs » Set up Splunk Log Observer Connect

Set up Splunk Log Observer Connect 🔗

Set up Log Observer Connect by integrating Log Observer with Splunk Enterprise. To set up Log Observer Connect, follow these steps:

  1. In Observability Cloud, go to Settings > Log Observer Connect and click Add new connection.

  2. Follow the instructions in the integration wizard to do the following in Splunk Enterprise:

    1. Create a new Splunk Enterprise role.

    2. Select the Splunk Enterprise indexes that you want to search in Log Observer Connect.

    3. Create and configure a new Splunk Enterprise user.

    4. Obtain certificates for securing inter-Splunk communication. See Configure and install certificates in Splunk Enterprise for Splunk Log Observer Connect to learn how.

Note

Manage concurrent search limits using your current strategy in Splunk Enterprise. All searches initiated by Log Observer Connect users go through the service account you create in Splunk Enterprise. For each active Log Observer Connect user, four backend searches occur when a user performs a search in the Log Observer Connect UI. For example, if there are three concurrent users accessing the Log Observer Connect UI at the same time, the service account for Log Observer Connect initiates 12 searches in Splunk Enterprise.